Role-Based Access Controls in AI Applications
Access to sensitive data in AI apps is restricted based on user roles.
Plain language
This control ensures that people can only access sensitive information in AI applications if they have a role that needs it. Without these restrictions, sensitive data could fall into the wrong hands, leading to privacy breaches and potential business losses.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2025
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentTopic
Excessive AgencyOfficial control statement
Role-based access controls are implemented for AI applications to restrict access to sensitive data.
Why it matters
If role-based access controls aren't used, sensitive data could be accessed by unauthorised users, potentially leading to data breaches and financial loss.
Operational notes
Regularly review and update user roles to accommodate job changes or personnel shifts, ensuring access to sensitive data remains appropriate.
Implementation tips
- Managers should assign roles carefully: Identify the employees who need access to sensitive data within AI applications based on their job responsibilities. Document their roles and ensure they are updated as responsibilities change.
- IT teams should set up user accounts: Configure the software to link each user account to their assigned role, which dictates the level of access to data they have. Use software tools that allow for easy role-based access settings.
- HR should train employees on access policies: Provide clear guidelines to staff about data access and privacy rules relevant to their roles. Conduct regular training to reinforce these policies and ensure understanding.
- System owners should review access permissions periodically: Schedule regular checks (at least quarterly) to ensure that who has access to sensitive data aligns with current job roles and tasks. Adjust roles as job functions evolve.
- Security teams should audit access logs: Use software to track and monitor who accesses what information and when, allowing for quick detection of any unauthorised access attempts.
Audit / evidence tips
- Askthe role-based access control policy document: Check this document to see if it outlines how roles are assigned and access is managed. Good if it details roles, responsibilities, and the process for changing access
- Goodoutcome shows correct alignment with minimal discrepancies
- Askto see recent access log reports: Review these logs for entries showing anomalous access attempts or misuses of access rights. Good results show consistent, authorised access patterns with no irregular activity
- Request documentation of recent role reviews: Check for records of when access roles were last reviewed and updated. Good if there is documented evidence of regular reviews with clear notes on changes made.
- Asktraining records on access policy: Review employee training completion records to confirm that staff received instructions on access policies. Good if all relevant staff have completed up-to-date training
Cross-framework mappings
How ISM-2093 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 5.15 | ISM-2093 requires organisations to implement RBAC in AI applications to prevent unauthorised access to sensitive AI data | |
| Annex A 8.3 | ISM-2093 requires RBAC for AI applications to restrict access to sensitive AI data | |
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.18 | ISM-2093 requires RBAC enforcement in AI applications so only authorised roles can access sensitive AI data | |
handshakeSupports(1)expand_less | ||
| Annex A 5.3 | Annex A 5.3 requires organisations to segregate conflicting responsibilities to reduce opportunities for misuse, fraud or error | |
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| E8-RA-ML3.1 | ISM-2093 requires role-based access controls (RBAC) for AI applications to restrict access to sensitive AI data to authorised personnel | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.